PodcastsComedySmashing Security

Smashing Security

Graham Cluley
Smashing Security
Neueste Episode

472 Episoden

  • Smashing Security

    This AI security flaw might be impossible to fix

    03.06.2026 | 57 Min.
    A website called "UK visa portal" has been quietly collecting passport scans, selfies, and personal data from thousands of travellers who thought they were applying through official channels. They weren't. And when a journalist tried to warn the company, it was lawyers who responded.
    Meanwhile, a paper from Cornell suggests that prompt injection - the technique malicious actors use to trick AI agents into doing things they really shouldn't - may be fundamentally unsolvable. Which is err... awkward, because everyone is rushing to plug AI agents into their email, files, and corporate networks.
    Plus don't miss our featured interview with Andrea Sivieri of CoreView, who tells us how hackers can lock your entire organisation out of its Microsoft 365 environment... without having to trick you into running a single piece of malicious code or handing over a password.
    All this and more in episode 470 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Tanya Janca.

    EPISODE LINKS:
    Hackers Simply Asked Meta AI to Give Them Access to High-Profile Instagram Accounts. It Worked - 404 Media.
    Canon Printer Vulnerability Leaks Plaintext Credentials - Praetorian.
    Password manager Dashlane says hackers stole some customers' password vaults - TechCrunch.
    UK Visa Portal exposed thousands of applicants’ passports and selfies — then called the lawyers on us - TechCrunch.
    AI Agents May Always Fall for Prompt Injections - ArXiv.
    MCP Security Crisis: Systemic Design Flaws in AI Agent Infrastructure - Cloud Security Alliance.
    From Preventive to Reactive: How AI Coding Assistants Transform Developers' Security Awareness - ArXiv.
    Design details that feel like magic - Design Spells.
    Singing lessons.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.
    ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    What your Oura ring won't tell you

    27.05.2026 | 53 Min.
    CISA, the US government agency whose entire job is keeping America's critical infrastructure safe from hackers, has had a contractor publish dozens of plain-text credentials to a public GitHub profile.
    Meanwhile, your Oura ring is quietly transmitting some of its data unencrypted - and when one journalist asked the company how often it hands user data to law enforcement, the answer was quite telling.
    Plus don't miss our featured interview with OPSWAT's Benny Czarny about his new book "Cybersecurity Upside Down."
    All this and more in episode 469 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Lesley Carhart.

    EPISODE LINKS:

    Canadian man arrested by international authorities, charged with administrating KimWolf DDoS botnet - US Dept of Justice.
    700+ education and tech websites hijacked in huge ClickFix malware campaign - Malwarebytes.
    Leaked Documents Reveal Russian ‘Cognitive Strikes’ Against the West - Including Islamophobic ‘Pig Head’ Attacks in Paris - OCCRP.
    Lawmakers Demand Answers as CISA Tries to Contain Data Leak - Krebs On Security.
    US cybersecurity agency CISA reportedly in dire shape amid Trump cuts and layoffs - TechCrunch.
    Oura says it gets government demands for user data. Will it share how many? - This Week In Security.
    Privacy and transparency of fitness tracking devices - Whyli.
    Upfest - Europe’s largest street-art festival.
    Magnets Are Bad For Hardware Again - Hackaday.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    High-speed train hacks and homicidal lawnmowers

    20.05.2026 | 55 Min.
    A 23-year-old radio enthusiast spent £300 on a piece of kit from the internet, and used it to bring four packed high-speed trains to a screeching halt. His defence in court? Possibly the most creative excuse we've heard all year.
    Meanwhile, owners of $4,000 robot lawnmowers are discovering that their gadget can be hijacked over the internet, redirected at journalists who foolishly lie down in front of it, and used to harvest Wi-Fi passwords, email addresses, and GPS coordinates. Change the default password? Sure - until the next firmware update silently resets it back.
    Plus - don't miss our featured interview with XBOW's Brendan Dolan-Gavitt about how AI is transforming penetration testing.
    All this and more in episode 468 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Geoff White.

    EPISODE LINKS:

    Open source tool maker Grafana Labs says hackers stole its code, refuses to pay ransom - TechCrunch.
    Man accused of stealing Beyoncé’s unreleased music takes guilty plea - ABC News.
    Shai-Hulud code drop: Open season for supply chain attacks- ReversingLabs.
    Student hacked Taiwan high-speed rail to trigger emergency brakes - BleepingComputer.
    Polish teen derails tram after hacking train network - The Register.
    The Cheap Radio Hack That Disrupted Poland's Railway System - WIRED.
    The man with an army of Yarbo robot lawn mowers - The Verge.
    Ever been run over by a robot? I have - for science! - TikTok.
    RD280UA 28” WQXGA BenQ Programming Monitor with Backlight and Flexible Arm - BenQ.
    Kai Shun DM-0708 combination sharpening stone, grain 300/1000 - Knives and Tools.
    AI-Assisted ICS Attack on a Water Utility - Dragos.
    Adversaries Leverage AI for Vulnerability Exploitation, Augmented Operations, and Initial Access - Google Cloud Blog.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    XBOW - The autonomous offensive security platform that helps security teams scale. Start a pentest today.
    OPSWAT - Read Benny Czarny's book, "Cybersecurity Upside Down", to rethink how you protect your organization from file-based threats, including those powered by AI.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    How ShinyHunters hacked the world's biggest universities

    13.05.2026 | 1 Std. 4 Min.
    Welcome to the largest educational data breach in history - affecting nearly 9,000 institutions, every Ivy League university, and 30 million students mid-finals. When Canvas's parent company refused to pay and announced they had deployed "security patches" instead, the hackers were less than impressed. So they came back through the cat flap.
    Meanwhile, a famous finance expert's face has been showing up on Facebook adverts promising hot stock tips and exclusive WhatsApp investment groups. Spoiler: it isn't him, the tips aren't real, and you're about to be scammed.
    Plus we chat to Mike Nichols of Elastic, about how the SOC isn't dying, attackers and defenders are both deploying AI agents, and how the real security crisis is no longer human users - it's the bots acting on their behalf.
    All this and more in episode 467 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Danny Palmer.

    EPISODE LINKS:

    ICO fines South Staffordshire £963K over 2022 breach - The Register.
    US bank reports itself after AI customer data mishap - The Register.
    Hackers abuse Google ads, Claude.ai chats to push Mac malware - Bleeping Computer.
    Canvas hack: What we know about apparent cyberattack that impacted thousands of schools - CNN.
    Canvas hack: Company pays criminals to delete students' stolen data - BBC News.
    Post by @amosmagliocco.bsky.social - Bluesky.
    Post by @sethcotlar.bsky.social - Bluesky.
    The Architecture of Deception: How a $187 Million Fraud Ecosystem Exploits Trust Across Australia and the United States - Group IB.
    The Fake Nobel that Duped the Romanian Academy - Scena9.
    A (Very) Short History of Life On Earth by Henry Gee - Waterstones.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    Elastic – AI is transforming security operations, but security is still a data problem. Learn how context-rich data drives faster, more reliable defence.
    CoreView - How secure is your Microsoft 365 tenant? Find out with CoreView's free Microsoft 365 Tenant Security Scanner.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
  • Smashing Security

    Meta sees everything, Copy Fail, and a deepfake gets hired

    06.05.2026 | 1 Std. 2 Min.
    Meta's smart glasses promise privacy "designed for you" - but everything they record was being beamed off to workers in Nairobi to label by hand. When those workers blew the whistle, Meta sacked all 1,108 of them.
    Meanwhile, the IT press is in a frenzy over a new Linux bug called "Copy Fail" - complete with logo, dedicated website, and a marketing-friendly name. But is it really the disaster everyone's making it out to be?
    And in our featured interview, Jake Moore of ESET explains how he tricked a company into offering his deepfake clone a job - after a perfectly normal-looking video interview.
    All this and more in episode 466 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, joined this week by special guest Paul Ducklin.

    EPISODE LINKS:
    Anti-DDoS Firm Heaped Attacks on Brazilian ISPs - Krebs On Security.
    Microsoft Defender wrongly flags DigiCert certs as Trojan:Win32/Cerdigent.A!dha - Bleeping Computer.
    Trellix confirms data breach after hack of 'a portion' of its source code - TechRadar.
    Meta’s AI Smart Glasses and Data Privacy Concerns: Workers Say “We See Everything” - Svd.
    Dispute over fate of Kenyan workers who saw Meta AI glasses films - BBC News.
    Copy Fail - CVE-2026-31431.
    Copy Fail: Hype versus reality - the full story - SolCyber.
    Flight into Danger: The Original Airplane! - BBC Sounds.
    The Luton writer behind the original Airplane! - BBC News.
    Code Dependent by Madhumita Murgia - Pan Macmillan.
    The Code Book - Simon Singh.
    Smashing Security merchandise (t-shirts, mugs, stickers and stuff)

    SPONSORS:
    Vanta - Expand the scope of your security program with market-leading compliance automation… while saving time and money. Smashing Security listeners get $1000 off!
    ESET - 30 years of threat research behind unique global telemetry, AI-native technology, and human expertise working together to keep your business protected.
    Action1 - Keep your systems safe (and your sanity intact) with the patch management platform that just works. The best part? Your first 200 endpoints are free, forever, with no functional limits.

    SUPPORT THE SHOW:
    Tell your friends and colleagues about “Smashing Security”, and leave us a review on Apple Podcasts or Podchaser.
    Become a supporter! Join Smashing Security PLUS via Patreon or Apple Podcasts for ad-free episodes on our early-release feed!

    FOLLOW THE SHOW:
    Follow us on Bluesky or Mastodon, or on the Smashing Security subreddit, and visit our website for more episodes.

    THANKS:
    Theme tune: "Vinyl Memories" by Mikael Manvelyan.
    Assorted sound effects: AudioBlocks.

    Privacy & Opt-Out: https://redcircle.com/privacy
Weitere Comedy Podcasts
Über Smashing Security
Stories from the world of hacking, cybersecurity, and rogue AI.Smashing Security isn’t your typical tech podcast. Hosted by cybersecurity keynote speaker and industry veteran Graham Cluley, it serves up weekly tales of cybercrime, hacking horror stories, privacy blunders, and tech mishaps - all with sharp insight, a sense of humour, and zero tolerance for tech waffle.Winner of the best and most entertaining cybersecurity podcast awards in 2018, 2019, 2022, 2023, and 2024, Smashing Security has had over ten million downloads. Past guests include Garry Kasparov, Mikko Hyppönen, and Jack Rhysider.Follow the podcast on Bluesky at @smashingsecurity.com, and subscribe for free in your favourite podcast app.New episodes released at 7pm EST every Wednesday (midnight UK).
Podcast-Website

Höre Smashing Security, Hobbylos und viele andere Podcasts aus aller Welt mit der radio.de-App

Hol dir die kostenlose radio.de App

  • Sender und Podcasts favorisieren
  • Streamen via Wifi oder Bluetooth
  • Unterstützt Carplay & Android Auto
  • viele weitere App Funktionen
Rechtliches
Social
v8.9.7| © 2007-2026 radio.de GmbH
Generated: 6/4/2026 - 3:37:31 PM